misp-warninglists icon indicating copy to clipboard operation
misp-warninglists copied to clipboard

Potential Malicious IP on "Warning List of known Microsoft Azure Datacenter IP Ranges"

Open Tyrell20 opened this issue 1 year ago • 0 comments

Hi All, We used the warning list of "Microsoft Azure Datacenter IP Ranges" but we are facing to different IP with massive inbound scan activity. We kindly ask to evaluate to divide the list considering apart from Indian IP.

In particular we received scan event from:

  • 4.224.240.93 --> 4.224.0.0/13
  • 40.80.93.32 -->40.80.64.0/19
  • 20.219.155.180 -->20.218.0.0/15

Alternatively, is it possible to consider excluding these subnets from the waning list?.

Thanks.

Tyrell20 avatar Feb 08 '24 09:02 Tyrell20